Privacy Policy

1. Controller and contact

Hephaistos is operated by the project's individual maintainer. For privacy requests, contact dpo@olympe.tech (data protection officer) or contact@olympe.tech. Full publisher identification under LCEN article 6-III is available in the legal notice.

2. The short version

Hephaistos is designed as a gateway to an AI backend: either a self-hosted server you control, or paid Hephaistos Cloud hosting when you choose not to operate your own server. That does not mean there is no cloud at all: accounts, sync, storage, notifications, subscriptions and optional managed services use technical providers disclosed below.

3. Data we process

4. Providers and location

Exact regions depend on the configured Supabase/Firebase/Cloudflare/Sentry projects and whether the user chooses self-hosting or paid Hephaistos Cloud hosting.

5. End-to-end encrypted DMs

DM v2 messages are encrypted client-side. The server stores encrypted content and protocol metadata needed for delivery and replay protection. To make history reload work on a device, decrypted plaintext may be cached locally in secure storage such as iOS Keychain or Android Keystore. That local cache is wiped when you reset app data or delete your account from that device.

6. Retention and deletion

You can export, reset or delete your data from the app. Account deletion triggers database cleanup and queued storage purges for avatars, attachments and uploaded documents. Audit logs may be retained and anonymized where needed for security, fraud prevention and legal obligations.

7. Legal basis

8. Your rights

Depending on your jurisdiction, you may request access, rectification, deletion, portability, restriction or objection. You may also lodge a complaint with the CNIL or your local data protection authority.

9. Cookies and analytics

The public website does not require advertising cookies. If analytics are added later, they must be disclosed here before deployment.